What it is, and what it is not

In 4 weeks, understand where you stand and what to do next.

This is not an independent audit or a certification. It is consulting work: it organises readiness and sets out, in writing, what is missing and in what order.

The path

  1. Discover
  2. Assess
  3. Prioritize
  4. Roadmap

What you receive

  • AI Inventory
  • Maturity Score
  • Risk Heatmap
  • Governance Gaps
  • Data Readiness
  • 90-Day Roadmap

This is not an independent audit or a certification. It is consulting work: it organises readiness and sets out, in writing, what is missing and in what order.

Four maturity levels

The G0–G3 path describes capabilities, not a grade. Placing an organisation at a level is a starting point for decisions, not a result to publish.

  1. Informal

    AI is used in a fragmented way, without policy or oversight. The main risk is exposing information in uncontrolled tools.

    Typical evidenceNo systematic evidence: the first step is a base policy and an inventory.

  2. Defined

    An approved leadership policy exists and a decision body has been constituted. Use cases are inventoried and classified by risk.

    Typical evidenceConstitution record of the decision body and a register of use cases.

  3. Managed

    Privacy and security controls are integrated into the development and procurement cycle. Impact assessments are carried out systematically.

    Typical evidenceImpact assessments and technical documentation per critical system.

  4. Optimised

    Governance is part of how the organisation works, with recurring external review and continuous improvement.

    Typical evidenceTransparency reports and results of external reviews.

What counts as evidence

A self-assessment is not an audit or a certification. The framework organises the preparation; independent verification, where it applies, is carried out by a qualified third party.

  • A register of AI systems in use, with owner and risk classification.
  • An approved policy, with date, scope and the body that approved it.
  • An impact assessment for a system, with identified risks and their treatment.
  • A record of vendor reviews and of the results delivered.

The starting point

Twelve questions about AI and data use in your organisation. An AGORA professional reviews them and sends you a written response by email.